Solution · ISO/IEC 27001:2022
An ISMS you can show the auditor, not just describe
ISO/IEC 27001:2022 requires a managed information-security management system — clauses 4 to 10 — supported by the 93 Annex A controls. Secantra holds the risk assessment, applicability decisions, controls and evidence in one record so certification and surveillance audits run from the system, not from a folder.
- Instrument
- ISO/IEC 27001:2022 (with ISO/IEC 27002:2022 guidance)
- Applies from
- Voluntary certification; 2013 certificates transition to 2022 by 31 October 2025
- Who
- Any organisation seeking certification or customer assurance; often demanded in procurement
- Supervision
- Accredited certification bodies; stage 1 / stage 2 and annual surveillance audits
Mapping
What ISO 27001 asks — and where it lives in Secantra
Status is stated honestly: LIVE is in the product today, PARTLY means the data model supports it but a workflow is not in the current release, PLANNED means not yet. Frameworks ship as curated, versioned libraries (ISO/IEC 27001 Annex A 93 requirements, DORA 29, NIS2 21 today) that you extend with tenant requirements — not verbatim reproductions of the legal text.
| ISO 27001 area | Clause | What is expected | In Secantra | Status |
|---|---|---|---|---|
| Risk assessment & treatment | 6.1.2, 6.1.3, 8.2–8.3 | Identify, analyse and evaluate information-security risks; select controls; produce a treatment plan. | Risk register with structured assessment, treatment plans and formal acceptance — linked to the assets and controls concerned. | LIVE |
| Statement of Applicability | 6.1.3 d) | List the necessary controls, whether implemented, and justify inclusions and exclusions. | Applicability per requirement with reasons is the SoA data; the control library records implementation status. | LIVE |
| Annex A controls | A.5–A.8 | 93 controls across organisational, people, physical and technological themes. | Controls from templates or your own; evidence with recency rules; findings for gaps; posture per theme. | LIVE |
| Documented information | 7.5 | Create, update and control the documents and records the ISMS requires. | Governance documents with templates, revisions and review / approval workflows; files with retention. | LIVE |
| Asset inventory & ownership | A.5.9, A.5.10 | An inventory of information and associated assets, with owners and acceptable-use rules. | The CMDB with owners, criticality and structural relationships; quality workspace for the gaps. | LIVE |
| Internal audit & management review | 9.2, 9.3 | Planned internal audits and management reviews at planned intervals, with recorded results. | Assessment cycles against adopted requirements; audit-ready record of decisions. Reviews scheduled with reminders. | PARTLY |
How it runs
A ISO 27001 programme in Secantra
- 01
Adopt ISO/IEC 27001:2022
Pin the published version; scope the ISMS; decide applicability per clause and control.
- 02
Map assets and owners
Information assets, the services and solutions they belong to, and the accountable owners.
- 03
Assess risk, attach controls and evidence
Risk register drives control selection; evidence with recency rules keeps it current between audits.
- 04
Show the auditor the record
SoA data, control coverage, evidence and findings — and generated reports from the record: framework status, risk register, executive summary.
Questions ISO 27001 teams ask
Does Secantra generate the Statement of Applicability document?
It holds the SoA data — applicability with justification and control status — from which the document is produced; the format is yours or your auditor's.
We are certified against the 2013 edition — what changes?
The 2022 controls are a different published version; you transfer the adoption explicitly and the superseded one stays as history.
Can auditors get read access?
Role-based access with tenant scope is how the platform works; how you grant an auditor a scoped, time-bounded role is an administrative setting.
See it on your own frameworks
A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.